Anonymous | Login
Project:
RSS
  
News | My View | View Issues | Roadmap | Summary

View Issue DetailsJump to Notes ] Issue History ] Print ]
ID
0057478
TypeCategorySeverityReproducibilityDate SubmittedLast Update
backport[Openbravo ERP] A. Platformmajorhave not tried2024-12-18 10:462025-02-26 17:55
ReporteramartinezView Statuspublic 
Assigned ToTriage Platform Base 
PrioritynormalResolutionfixedFixed in VersionPR24Q4.1
StatusclosedFix in branchFixed in SCM revision
ProjectionnoneETAnoneTarget VersionPR24Q4.1
OSAnyDatabaseAnyJava version
OS VersionDatabase versionAnt version
Product VersionSCM revision 
Merge Request Statusapproved
Review Assigned To
OBNetwork customerGold
Web browser
ModulesCore
Support ticket
Regression level
Regression date
Regression introduced in release
Regression introduced by commit
Triggers an Emergency PackNo
Summary

0057478: broken layout in save view - Some flows are still broken

DescriptionThis issue is a continuation of https://issues.openbravo.com/view.php?id=56753 [^]

Improper names (ie. with some special characters) for standard windows saved views, can break the layout when they are displayed.

- The problem is still being reproduced on the Delete View flow
Steps To ReproduceIn a registered instance:

1. Log in backoffice
2. Open any window
3. In the toolbar click on Save View
4. Enter a name with invalid format and save
5. In that window click on Save View again to display the name of the view saved in the previous step
6. In Save View, select Save View
7. In Save View select Delete View
  ERROR: Broken layout
Proposed SolutionView names should be properly treated when they are going to be displayed.
TagsNo tags attached.
Attached Files

- Relationships Relation Graph ] Dependency Graph ]
blocks defect 0057477 closedTriage Platform Base broken layout in save view - Some flows are still broken 

-  Notes
(0176172)
hgbot (developer)
2025-02-26 17:53

Merge Request created: https://gitlab.com/orisha-group/bu-commerce/openbravo/product/openbravo/-/merge_requests/1557 [^]
(0176173)
hgbot (developer)
2025-02-26 17:55

Merge request merged: https://gitlab.com/orisha-group/bu-commerce/openbravo/product/openbravo/-/merge_requests/1557 [^]
(0176174)
hgbot (developer)
2025-02-26 17:55

Directly closing issue as related merge request is already approved.

Repository: https://gitlab.com/orisha-group/bu-commerce/openbravo/product/openbravo [^]
Changeset: 64ef35a1feaac91c5120c75ccb98a17a3b529757
Author: ALEJANDRO MARTINEZ <a.martinez@orisha.com>
Date: 26-02-2025 17:54:05
URL: https://gitlab.com/orisha-group/bu-commerce/openbravo/product/openbravo/-/commit/64ef35a1feaac91c5120c75ccb98a17a3b529757 [^]

Fixes ISSUE-57478: Complete character escaping in delete view to cover all XSS injection points

---
M modules/org.openbravo.client.application/web/org.openbravo.client.application/js/main/ob-standard-window.js
M modules/org.openbravo.client.application/web/org.openbravo.client.application/js/personalization/ob-manage-views-popups.js
M modules/org.openbravo.client.application/web/org.openbravo.client.application/js/personalization/ob-manage-views-toolbar.js
---

- Issue History
Date Modified Username Field Change
2024-12-18 10:47 amartinez Type defect => backport
2024-12-18 10:47 amartinez Target Version => PR24Q4.1
2025-02-26 17:53 hgbot Merge Request Status => open
2025-02-26 17:53 hgbot Note Added: 0176172
2025-02-26 17:53 hgbot Merge Request Status open => approved
2025-02-26 17:55 hgbot Note Added: 0176173
2025-02-26 17:55 hgbot Resolution open => fixed
2025-02-26 17:55 hgbot Status scheduled => closed
2025-02-26 17:55 hgbot Fixed in Version => PR24Q4.1
2025-02-26 17:55 hgbot Note Added: 0176174


Copyright © 2000 - 2009 MantisBT Group
Powered by Mantis Bugtracker